BigCommerce alerts merchants that attackers may have caused data breaches tied to third-party Ribon applications. Multiple outlets report that the compromise begins with stolen or misused credentials related to Ribon apps. The attackers then gain access to affected stores and inject malicious scripts, potentially exposing customers and website visitors.
SecurityWeek and Bleeping Computer both describe the intrusion as credential-driven and linked to the Ribon ecosystem. SecurityWeek states the attackers use a compromised BigCommerce application key associated with Ribon to access customer data. Bleeping Computer similarly says attackers compromise credentials for third-party Ribon apps and use them to inject harmful scripts into online stores. The outlets differ mainly in emphasis—one focusing more on customer data access via an application key, the other on script injection and merchant notifications. Both frame the event as an incident impacting merchant websites where the Ribon apps are used, prompting BigCommerce to notify affected merchants and advise on response steps.